DEFENDERS CLOCK
THE PUBLIC OPERATING SIGNAL FOR DEFENDERS
ISSUED 2026-09-21 · 14:00 UTC
ARCHIVED READING · PERMANENT RECORD

WEEK OF SEPTEMBER 21, 2026

73/ 100HIGH PRESSURE

Passkey-themed social engineering graduates from research to active intrusions, while exploitation holds at its peak behind a max-severity Cisco ISE zero-day.

↑ 1 POINT SINCE LAST WEEK2026-W39ISSUED 2026-09-21 · 14:00 UTCMETHODOLOGY V1.0

SIGNALS

ACTIVE EXPLOITATION
STEADY

Held at last week's peak: a CVSS 10.0 Cisco ISE zero-day and a Secure Email Gateway root-execution flaw join eight current KEV additions; the Chrome-Windows zero-day chain is now attributed in ongoing intrusions.

CONFIDENCE · HIGH
IDENTITY & HUMAN ATTACK PRESSURE
RISING

The passkey watch item converts: Microsoft confirms passkey-themed social engineering in active cloud intrusions — helpdesk-impersonation lures driving AitM and device-code flows against the control defenders migrated to.

CONFIDENCE · MEDIUM
INTRUSION / RANSOMWARE TEMPO
STEADY

A quieter disclosure week: one material-incident follow-up filing and a large consumer-platform breach; tempo holds at the recent raised level.

CONFIDENCE · MEDIUM

THREE MOVES THIS WEEK
01Patch the Cisco ISE zero-day now and audit ISE admin-API activity — a CVSS 10.0 bypass of the identity layer is compromise-assumed territory.
02Tell staff plainly: no real helpdesk asks you to update passkeys or MFA via a link or SMS — route every such request to a verified internal channel.
03Patch ScreenConnect and Artifactory again and review their access logs — remote-management and artifact infrastructure keep recurring in KEV.

WHY WE BELIEVED THIS

RECEIPT LOG · WEEK 3910 RECEIPTS
CISA KEV · ANCHORCISA adds Cisco ISE and Acronis Backup CVEs to the KEV catalogEight current-year KEV additions in the window overall EXPLOITATION · 2026-09-16
VENDOR ADVISORY · CORROB.Cisco advisory: ISE authentication bypass (CVE-2026-76460, zero-day, exploited) EXPLOITATION · 2026-09-16
INCIDENT REPORTING · CORROB.BleepingComputer: Cisco warns of max-severity ISE zero-day exploited in attacks EXPLOITATION · 2026-09-17
VENDOR RESEARCH · ANCHORMicrosoft Security Blog: passkey-themed social engineering leads to identity and cloud compromisePublished Sep 9 (previous window), surfaced via this week's reporting; converts W34's research-only watch item to observed intrusions IDENTITY · 2026-09-09
INCIDENT REPORTING · CORROB.The Hacker News: N0va phishing kit targets US and EU businesses IDENTITY · 2026-09-16
PUBLIC DISCLOSURE · ANCHORNutex Health SEC 8-K: materiality-assessment update to its Item 1.05 incidentFollow-on filing to the Aug 31 material-incident disclosure, not a new incident INTRUSION · 2026-09-11
INCIDENT REPORTING · CORROB.The Hacker News: Gyazo breach exposes 23.62 million user records INTRUSION · 2026-09-17
REVISION HISTORY
2026-09-21 · 14:00 UTCOriginal publication.
READINGS ARE IMMUTABLE ONCE PUBLISHED · CORRECTIONS APPEND TO THE REVISION HISTORY ABOVE · RUBRIC AT /METHODOLOGY
← FULL ARCHIVE